Privacy Policy

Last updated: August 18, 2026

This Privacy Policy explains how Techsolid Automation Limited ("we", "us", "our") collects, uses, and protects information when you use rungs.dev, learn.rungs.dev, and studio.rungs.dev (the "Service").

Who we are

Techsolid Automation Limited is a private limited company registered in Ireland. We act as the data controller for personal data processed through the Service.

What we collect

Account and identity data

The Service uses Supabase (EU region, Ireland) to sign you in and to remember your progress across devices.

Exercise progress

When you run tests in an exercise on studio.rungs.dev, we upload the following to Supabase:

This data is stored in the exercise_progress table and is bound to your Supabase user UUID (anonymous or permanent). It powers the resume-across-devices feature and the progress chips on the exercise pages. Row-Level Security prevents other users from reading your rows; our team may read exercise snapshots only to investigate and fix Service or exercise issues.

To produce aggregate dashboards (counts of started and completed exercises per day, active learners), we sync a subset of exercise_progress to PostHog's EU Data Warehouse: exercise slug, status, attempt counts, timestamps, and which language(s) you solved in. Your AOI snapshot — the actual code you write — is never synced to PostHog. The sync runs through a least-privilege Postgres role that physically cannot read the snapshot column.

Purchases (Learn Plus)

If you buy a Plus access pass on rungs.dev, checkout is operated by Paddle, our merchant of record. Paddle collects the data needed to process the order — name, email address, billing country, payment details, and tax information — and acts as an independent data controller for that data under its own privacy policy. When you start checkout, we share your account email address with Paddle so it is pre-filled for you — this happens when the checkout opens, even if you don't complete the purchase.

We never see or store your payment card details. After a successful purchase we receive and store, linked to your account: the product purchased, the Paddle transaction identifier, and the purchase and expiry timestamps. We use this only to unlock paid exercises for your account and to handle refunds or support requests.

Group and classroom enquiries

The group enquiry form on /pricing/groups is the one place on the Service where we ask you for personal data directly, and you do not need a permanent account to use it. When you submit it we collect the name, email address, and organisation you enter, and, if you fill them in, your role, the number of people you are enquiring for, and anything you write in the free-text field.

We use this solely to answer your enquiry. The submission is delivered as an email to our support inbox by Resend, our email processor, with your address set as the reply-to so we can respond; it is not added to any marketing list, and we do not send you anything other than a reply unless you ask us to. The lawful basis is our legitimate interest in responding to a business enquiry you initiated.

The enquiry lives in our support inbox rather than in a database. We keep it while we are in contact with you and for up to 24 months afterwards, so we can pick up a conversation you return to; you can ask us to delete it sooner at privacy@rungs.dev.

Analytics data

We use PostHog (EU instance, eu.i.posthog.com) to understand how the Service is used. PostHog may collect:

Analytics data is processed in the European Union via PostHog's EU infrastructure. While most of the Service does not require account registration, analytics and service providers may still process online identifiers and similar technical data.

We measure usage in one of two ways, depending on your cookie choice. If you accept analytics cookies, we use cookie-based analytics that can recognise you across visits. If you decline, or have not yet chosen, we fall back to cookieless measurement: a privacy-preserving identifier is generated on our analytics provider's servers, sets no cookie on your device, is not stored as a persistent identifier, and does not build a personal profile. This lets us count visitors and overall usage without tracking you individually.

Bot-detection data

We use Cloudflare Turnstile in invisible mode to defend our sign-in endpoints — anonymous sign-in and email one-time-code requests — from automated abuse. Turnstile collects browser signals (IP address, user-agent, JavaScript fingerprints, mouse and timing patterns) and returns a short-lived token that we forward to Supabase. We do not see the underlying signals; we only see the pass/fail outcome.

Cookies

We use strictly necessary cookies for sign-in (Supabase auth tokens on .rungs.dev), bot defence (Cloudflare Turnstile), and share-link tracking. We use analytics cookies for PostHog (visitor and session identifiers). Analytics cookies are not set unless you Accept on our cookie banner, and session recordings (see "Analytics data") likewise only start after you Accept. If you decline, see "Analytics data" for how we still measure usage without cookies. A browser Do Not Track signal is treated the same as declining.

You can change your choice at any time using the Cookie settings link in the footer of this site, or by clearing your browser's cookies for .rungs.dev. Blocking strictly-necessary cookies will break sign-in.

Search on rungs.dev runs on our own servers — your query is sent to rungs.dev, matched against an index of our documentation, blog posts, and exercises, and the results are returned. No third-party search provider receives it, and we store no search history or recent-search cookies. Do not include personal or sensitive information in search queries.

Relay AI Assistant

Relay is the AI tutor available in Studio's right sidebar (the Relay tab). When you send a message to Relay, the following are sent from your browser to our studio-assist server and forwarded to a third-party large language model provider:

The model provider processes your prompt to generate a reply and returns it through our server. We do not include AOIs you have not opened, AOIs from other Studio sessions, your other localStorage drafts, or your test results unless they are part of the active context above.

We capture each Relay turn in PostHog LLM Analytics (EU instance). For every turn we store: the prompt, the model reply, the model name, token counts, latency, an anonymous session identifier, the studio mode, and any feedback you provide. We use these traces to evaluate Relay quality, debug bugs, and improve the system prompt and underlying documentation. Individual turns may be read by our team when investigating issues.

Do not paste secrets, credentials, customer data, or proprietary code into Relay.

Relay is currently free during an early-access period. Paid AI features may be introduced later; if so, payment information will be handled by a third-party processor and this policy will be updated.

Communications

If you have a permanent account (so we hold your email address), we may email you for the following purposes:

Anonymous sessions have no email address and are never emailed. We do not sell or share your email address with third parties for their own marketing.

What we do not collect

AOI Sharing

When you use the optional Share feature, the AOI data you choose to share is uploaded to our database (hosted on Supabase, EU region) and made publicly accessible via a link. Shared AOIs are:

You can share AOIs at your discretion. Do not share AOIs containing proprietary or confidential logic.

Shared AOIs may be used to operate, secure, and improve the Service, including developing, evaluating, and training machine learning and AI features. This applies only to AOIs you choose to share, not to AOIs stored locally in your browser or saved as exercise snapshots in your private exercise_progress rows.

Data Storage and Retention

DataLocationRetention
Non-exercise AOI projectsYour browser (localStorage)Until you clear browser data
Shared AOIsSupabase (EU, Ireland)Indefinitely, or until we remove inactive shares
Exercise progress (snapshots, pass state)Supabase (EU, Ireland)Until you delete your account; anonymous accounts and their rows are pruned automatically after 180 days of inactivity
Supabase user recordSupabase (EU, Ireland)Permanent accounts retained until you request deletion; anonymous accounts pruned automatically after 180 days of inactivity
Purchase records (entitlements)Supabase (EU, Ireland)Until you delete your account; Paddle retains the underlying transaction records under its own policy
Analytics dataPostHog EUPer PostHog's data retention policy
Relay prompts and repliesPostHog EU (LLM Analytics)Per PostHog's data retention policy
Relay prompts (model provider)Third-party LLM providerPer the current provider's data retention policy
Turnstile signalsCloudflarePer Cloudflare's Privacy Policy
Group enquiries (name, email, org, notes)Our support inbox (Resend delivers)While we are in contact with you and up to 24 months afterwards, or sooner on request

Lawful basis for processing

We rely on legitimate interest for operating the editor, anonymous sign-in, bot defence, exercise progress storage, anonymous cookieless usage measurement, sending service and feedback messages to signed-in users, and replying to a group enquiry you send us; on performance of your request for sign-in via Google, GitHub, or an emailed one-time code, for processing your purchase and granting the resulting access pass, and for each Relay message you send; and on your consent — given via the cookie banner, the sign-in panel, each Share action, or by opting in to optional product-update emails — for cookie-based product analytics, for AOIs you choose to share publicly, and for any optional marketing or newsletter communications.

Third-Party Services

ServicePurposeRegionPrivacy Policy
SupabaseAuth, exercise progress, and AOI sharing storageEU (Ireland, eu-west-1)supabase.com/privacy
Cloudflare TurnstileInvisible bot detection on sign-in endpointsGlobal, with EU presencecloudflare.com/privacypolicy
GoogleOAuth identity provider when you sign in with GoogleUS (transfer covered by EU SCCs)policies.google.com/privacy
GitHubOAuth identity provider when you sign in with GitHubUS (transfer covered by EU SCCs)docs.github.com/site-policy/privacy-policies
PaddleMerchant of record — checkout, payment, tax, receiptsUK/EU (independent data controller)paddle.com/legal/privacy
PostHogProduct analytics and LLM analyticsEUposthog.com/privacy
ResendDelivers our emails — sign-in codes and group enquiriesUS (transfer covered by EU SCCs)resend.com/legal/privacy-policy
Large language model providerGenerates Relay AI assistant repliesSee the "Current AI Model Provider" sectionThe current provider is listed at the bottom of this page; we may change providers without re-issuing this policy
VercelHosting, CDN, and AI Gateway routing for Relay promptsEU edge for delivery; account metadata in USvercel.com/legal/privacy-policy

For processors located outside the EEA (Cloudflare, Google, GitHub, Resend, the Relay AI model provider, Vercel account metadata) we rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

Your Rights

If you are in the EU/EEA, you have rights under GDPR including the right to access, rectify, port, restrict, object to the processing of, and erase your personal data, and the right to lodge a complaint with a supervisory authority. Our supervisory authority is the Irish Data Protection Commission (dataprotection.ie).

You can:

For anonymous accounts specifically: there is no email to identify you by, so we can act on a deletion request only if you give us your anonymous UUID — which lives solely in the .rungs.dev cookie on your device. To have your data deleted, send us that UUID (or the cookie value) before you clear the cookie; once it is gone, neither you nor we can tell which rows are yours. Any anonymous account not identified this way is removed automatically after 180 days of inactivity.

Children's Privacy

The Service is not directed at children under 16. We do not knowingly collect information from children. If you believe a child has signed up, contact us at privacy@rungs.dev and we will delete the account.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date.

Contact

For privacy questions or data requests, contact us at:

Techsolid Automation Limited Email: privacy@rungs.dev

Current AI Model Provider

As of the "Last updated" date above, the third-party large language model provider used by Relay is OpenAI, reached through the Vercel AI Gateway — see openai.com/policies/privacy-policy and vercel.com/legal/privacy-policy. We may change providers at our discretion; the current provider will be reflected here.